โผ CVE-2022-40198 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet รขโฌโ For WooCommerce plugin <= 1.3.24 leading to plugin settings change.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1064 โผ
๐ Read
via "National Vulnerability Database".
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection.This issue affects Weighbridge Automation Software: before 1.1.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1117 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23973 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page รขโฌโ Contact People plugin <= 3.7.0.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-1116 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-23984 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu รขโฌโ circle floating menu plugin <= 3.0.1 leading to form deletion.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46797 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Conversios All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce plugin <= 5.2.3 leads to plugin settings change.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-38468 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin รขโฌโ NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.๐ Read
via "National Vulnerability Database".
๐ด CISA: ZK Java Framework RCE Flaw Under Active Exploit ๐ด
๐ Read
via "Dark Reading".
The flaw, which drew attention in October when it was found in ConnectWise products, could pose a significant risk to the supply chain if not patched immediately.๐ Read
via "Dark Reading".
Dark Reading
CISA: ZK Java Framework RCE Flaw Under Active Exploit
The flaw, which drew attention in October when it was found in ConnectWise products, could pose a significant risk to the supply chain if not patched immediately.
โผ CVE-2023-24755 โผ
๐ Read
via "National Vulnerability Database".
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-25222 โผ
๐ Read
via "National Vulnerability Database".
A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46806 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading to cart modification.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-25544 โผ
๐ Read
via "National Vulnerability Database".
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24756 โผ
๐ Read
via "National Vulnerability Database".
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-46798 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24757 โผ
๐ Read
via "National Vulnerability Database".
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24758 โผ
๐ Read
via "National Vulnerability Database".
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-45608 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in order to accomplish this, the attacker must know the corresponding API's parameter (authority : value).๐ Read
via "National Vulnerability Database".
โผ CVE-2022-47148 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-0594 โผ
๐ Read
via "National Vulnerability Database".
Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization. The stored XSS vulnerability was possible due the value of a span's attributes/resources were not properly sanitized and this will be rendered when the span's attributes/resources are expanded. An attacker needs to have the Editor role in order to change the value of a trace view visualization to contain JavaScript. This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard. Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-24567 โผ
๐ Read
via "National Vulnerability Database".
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.๐ Read
via "National Vulnerability Database".